Class SessionSignIn
How a chain signs a user in to a session, once some mechanism has established who they are. One per chain, shared by every mechanism of it, so that each ends the same way:
- the chain's
SecondFactorPolicy, if it has one, may hold the sign-in back and answer the request itself; - the session id changes and the CSRF token is replaced;
- the authentication becomes the request's and is saved for later ones;
- what follows a sign-in is told -- remember-me issues its cookie;
- the mechanism's
AuthenticationSuccessHandleranswers.
A sign-in filter calls success(HttpServer.Request, Authentication, AuthenticationSuccessHandler) with what its AuthenticationManager
returned, and failure(HttpServer.Request) when it was refused. What finishes a held-back
sign-in -- the filter that takes the one-time code -- calls complete(HttpServer.Request, Authentication, boolean, AuthenticationSuccessHandler).
-
Method Summary
Modifier and TypeMethodDescriptioncomplete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler) Signs the user in, with no second factor asked: for the first factor of a chain without one, and for whatever finishes a sign-in that was held back.complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler, boolean secondFactor) Signs the user in, and says whether a second factor was part of it.voidfailure(HttpServer.Request request) A mechanism refused the credentials it was given.success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler) A mechanism acceptedauthentication: signs the user in, unless the chain asks for a second factor first.success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler, boolean secondFactorSatisfied) A mechanism acceptedauthentication, and says whether what it checked was two factors already.
-
Method Details
-
success
public HttpServer.Response success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler) throws Exception A mechanism acceptedauthentication: signs the user in, unless the chain asks for a second factor first.- Returns:
- the answer to the request
- Throws:
Exception
-
success
public HttpServer.Response success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler, boolean secondFactorSatisfied) throws Exception A mechanism accepted
authentication, and says whether what it checked was two factors already.A passkey whose authenticator verified the user -- a fingerprint, a PIN -- is something they have and something they are or know, in one step: asking for a one-time code after it would add nothing, so the chain's
SecondFactorPolicyis not consulted. A mechanism that checked one factor passes false, and the policy decides as it does for a password.- Parameters:
secondFactorSatisfied- true when the sign-in needs no second factor whatever the chain's policy would say- Returns:
- the answer to the request
- Throws:
Exception
-
complete
public HttpServer.Response complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler) throws Exception Signs the user in, with no second factor asked: for the first factor of a chain without one, and for whatever finishes a sign-in that was held back.- Parameters:
rememberMe- whatSecondFactorPolicy.intercept(HttpServer.Request, Authentication, boolean)was told- Throws:
Exception
-
complete
public HttpServer.Response complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler, boolean secondFactor) throws Exception Signs the user in, and says whether a second factor was part of it. What finishes a sign-in that was held back passes true, and so a remember-me cookie issued here is one that may stand for both factors later; seeMfaConfigurer.- Parameters:
rememberMe- whatSecondFactorPolicy.intercept(HttpServer.Request, Authentication, boolean)was toldsecondFactor- whether the user presented a second factor- Throws:
Exception
-
failure
A mechanism refused the credentials it was given.
-